Closed Bug 1080606 Opened 11 years ago Closed 11 years ago

Update VLC plugin to 2.1.5

Categories

(Plugin Check Graveyard :: Whistler, defect, P1)

defect

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: devand27, Assigned: espressive)

Details

Attachments

(2 files)

User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36 Actual results: Firefox is using VLC plug-in 2.1.3. Its an old version of which is having some critical security issues. Expected results: Videolan has fixed some critical security issues in 2.1.5, so Firefox should mark older versions as outdated or vulnerable.
Component: Untriaged → General
OS: Windows 7 → All
Product: Firefox → Plugin Check
Hardware: x86_64 → All
Version: 35 Branch → unspecified
Firefox does not ship with this plug-in by default. You either have to add it during vlc installation or do so manaully. Plug-in check _might_ be able to help notify users so moving this there for an answer. Removing flag as the info is public
Group: core-security
Component: General → Blocklisting
Product: Plugin Check → addons.mozilla.org
Attached image Untitled.png
Hi Please find the attached screen shot that show VLC 2.1.3 is up-to-date for Firefox. Firefox should block these versions as out-dated. Vulnerabilities Fixed in 2.1.4 CVE-2014-3441 CVE-2014-1684 Vulnerabilities Fixed in 2.1.5 CVE 2014-0333 CVE 2014-3466 Thanks Chandra Mohan
Hi Please find the Video POC. Also the security vulnerability of VLC plug-ins versions before 2.1.5 version is very high. CVE-2014-3441 - denial of service (memory corruption) CVE-2014-1684 - denial of service (memory corruption) CVE 2014-0333 - denial of service (memory corruption) CVE 2014-3466 - denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a Server Hello message. Thanks Chandra Mohan
Component: Blocklisting → plugins.mozilla.org
Product: addons.mozilla.org → Websites
QA Contact: cbook
Assignee: nobody → schalk.neethling.bugs
Component: plugins.mozilla.org → Whistler
Priority: -- → P1
Product: Websites → Plugin Check
QA Contact: cbook
How do I get all the bugs off my phone someone else addad
How do I get all the bugs off my phone someone else addad
Plugin updated on production database.
Status: UNCONFIRMED → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Hi Thanks for the quick fix. Any bounty?
Hey, Why no reply?
I'm not involved with the bug bounty program, but I'm fairly sure this report doesn't qualify, since it's a bug in a third party plugin, and the only issue was the way we presented it. You can find the rules for the program here: https://www.mozilla.org/security/bug-bounty/
Hi Thanks for your reply. But here the bug is in the browser plug-in check.
It's not really part of the browser, but a webpage that is used to assist users to update their plugins. Also, pointing to a vulnerable version of a plugin doesn't necessarily mean the user will be attacked. And the bug would be on the plugin side, not the browser side. Plugins are click-to-activate by default, as an additional protection. I don't think this constitutes a major security problem, and the other people who have intervened in this bug seem to agree, since none of them marked it as such. We appreciate your help in filing this bug, but I don't think it qualifies for a bounty.
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: